Roles & Permissions allows you to automatically grant access to LearnDash courses or site roles based on customer purchases. You can also restrict content visibility to specific user roles. WooDonkey serves as your central dashboard for managing these settings, while the Companion plugin on your WooCommerce store enforces the access grants and content restrictions.
What it is
The Roles & Permissions feature is found in the WooDonkey sidebar under Site Settings, then Roles & Permissions. It is organized into three tabs: Access Rules, Content Restrictions, and Roles. The Site Users screen is a separate sidebar item for managing individual users. The sidebar label is Roles & Permissions.
How it helps you
This feature helps merchants automate access management and control content visibility on their WooCommerce stores. You can ensure that shoppers who purchase specific products automatically receive access to a LearnDash course or a designated user role. Additionally, you can restrict products, pages, posts, categories, and tags to be visible only to users with particular roles. This ensures that shoppers with the correct account permissions see the content intended for them.
What is included
Access Rules Tab: Manage rules that automatically grant access based on purchases.
- Purchase-based access rules: When a customer buys a specific product, grant them access to a LearnDash course or a site role. Access is granted when the order completes and revoked on refund or cancellation.
- New rule button: Create a new access rule.
- Empty state messages: ‘No access rules yet. Click “New rule” to get started.’ or ‘Select a store to manage permissions.’ if no store is selected.
- New access rule / Edit rule form: Configure the details of an access rule.
- Rule name: A descriptive name for the rule, e.g., ‘Buyers of WordPress course get course access’.
- Trigger products (buying any one of them): Search for products by name or SKU that will trigger the access grant.
- Permission type: Choose between ‘LearnDash course’ or ‘User role’.
- Courses / Roles selectors: Select the specific LearnDash course(s) or user role(s) to grant. The LearnDash option is only available if LearnDash is installed on the store.
- Revoke access on refund/order cancellation switch: Defaults to ON. When enabled, access is removed if the order is refunded, cancelled, or fails.
- Cancel and Save buttons.
- Toasts: ‘Select at least one product’, ‘Select at least one target (course/role)’, ‘Rule saved’, ‘Rule deleted’.
- Access rules list: Displays existing rules, showing the rule name (or ‘(no name)’ if not set), a ‘Disabled’ badge (rules are created as enabled and cannot be turned off via this form), the count of trigger products, and whether it grants a Course or Role. Each rule has Edit and Delete actions.
- Companion behavior for Access Rules: Access is granted when the WooCommerce order is completed. Access is revoked on refunded, cancelled, or failed order statuses if the ‘Revoke access on refund/order cancellation’ setting is ON. Guests without a WordPress user account are not granted access. LearnDash course access and WordPress user roles are updated on the store by the Companion plugin. Only enabled rules are pushed to the store. There is no shortcode for access rules.
Content Restrictions Tab: Manage rules that restrict content visibility.
- Content Restrictions: Show content (products, pages, posts, categories, and tags) only to visitors with a specific role.
- New rule button: Create a new content restriction rule.
- Empty state message: ‘No content restriction rules yet.’
- New content restriction / Edit rule form: Configure content visibility.
- Rule name: A descriptive name for the rule, e.g., ‘Content for practitioners’.
- Content type: Select the type of content to restrict: ‘Product’, ‘Page’, ‘Post’, ‘Product category’, ‘Product tag’, ‘Post category’, ‘Post tag’.
- Restricted items: Select the specific items of the chosen content type.
- Visible to roles (whitelist): Select the user roles that are permitted to see the content. A warning ‘No role selected – the content will be hidden from all visitors (except administrators)’ appears if no roles are chosen.
- Redirect URL (optional): An optional URL to redirect users who do not have access. The placeholder is
https://example.com/login. If left empty, unauthorized users will see a 404 error. - Active switch: Defaults to ON.
- Save button: Disabled if no restricted items are selected.
- Toasts: ‘Saved’, ‘Deleted’.
- Companion behavior for Content Restrictions: Restricted content is hidden from listings and search results. Users attempting direct access without the required role are redirected or see a 404 error. Store administrators always see all content. Logged-out users without a matching role will have content hidden. This feature controls display, not hard file or API security. There is no shortcode for content restrictions.
Roles Tab: Create and manage custom user roles.
- User roles: Create new roles in WordPress and choose which capabilities they have.
- New role button: Create a new user role.
- Loading/Empty state messages: ‘Loading roles…’, ‘Select a store to manage roles.’, or ‘No roles found (make sure the WooDonkey plugin is installed, active, and updated to the latest version on the store).’
- New role / Edit role form: Define a custom user role.
- Role name: A display name for the role, e.g., ‘Course student’.
- Identifier (slug): A unique, machine-readable name for the role. This field is locked when editing an existing role.
- Permissions: A list of capabilities that can be assigned to the role, with a count of selected permissions. A filter field helps search for specific permissions.
- Permission Groups: Capabilities are organized into groups: ‘Store management – products, orders, coupons’, ‘Course management (LearnDash)’, ‘User and role management’, ‘Content management – pages, posts, media’, ‘Site and settings management’, and ‘Additional permissions’. The ‘read’ capability is automatically added to allow login.
- Separate product pricing switch: Defaults to OFF. When ON, it enables separate regular and sale price fields for simple products for this role. Customers with this role will see and pay those specific prices in the store.
- Toasts: ‘Role saved’, ‘Role deleted’, ‘Role deleted · {{count}} users moved to {{target}}’.
- Delete role confirmation: When deleting a role, a confirmation dialog appears: ‘Delete the role “{{name}}”? Only users assigned solely to it will be moved to the default role (subscriber).’
- Non-deletable core roles: The following core WordPress roles cannot be deleted via the UI: administrator, editor, author, contributor, subscriber, customer, shop_manager.
Site Users (Related Screen): A separate screen for managing individual users.
- Navigation: Found under Site Settings, then Site Users.
- Title: Site Users.
- Search: Search users by name, email, or username.
- All roles filter: Filter users by their assigned roles.
- Export to CSV: Download user data.
- User actions: Edit User, New Password (optional), Email this user a password reset link.
- Pagination: Displays 50 users per page.
- Companion requirement: Requires the Companion plugin to be active on the store.
How to turn on and manage each capability
Create an Access Rule
- Go to Site Settings > Roles & Permissions.
- Click the Access Rules tab.
- Click the New rule button.
- Enter a Rule name.
- In Trigger products, search for and select the products that will grant access.
- Choose a Permission type: ‘LearnDash course’ or ‘User role’.
- Select the specific course(s) or role(s) to grant.
- (Optional) Toggle Revoke access on refund/order cancellation if you want access to be removed when an order is refunded, cancelled, or fails.
- Click Save.
Create a Content Restriction
- Go to Site Settings > Roles & Permissions.
- Click the Content Restrictions tab.
- Click the New rule button.
- Enter a Rule name.
- Select a Content type (e.g., ‘Product’, ‘Page’).
- In Restricted items, search for and select the specific content items to restrict.
- In Visible to roles, select the roles that are allowed to see this content.
- (Optional) Enter a Redirect URL for unauthorized users.
- Ensure the Active switch is ON.
- Click Save.
Create a Role
- Go to Site Settings > Roles & Permissions.
- Click the Roles tab.
- Click the New role button.
- Enter a Role name. The Identifier (slug) will be automatically generated.
- Select the desired Permissions for this role from the available groups.
- (Optional) Toggle Separate product pricing ON if you want to set unique prices for simple products for users with this role.
- Click Save.
Manage Site Users
- Assign a role to a user: Go to Site Settings > Site Users, search for the user, click Edit User, and assign the desired role(s).
- Send a password reset link: Go to Site Settings > Site Users, search for the user, and click Email this user a password reset link.
What to know before you start
- The Access Rules tab is the default view when you open Roles & Permissions.
- New access rules are saved as enabled by default, and there is no switch on the form to turn an access rule off.
- The ‘Revoke access on refund/order cancellation’ setting for access rules defaults to ON.
- Content restriction rules default to ‘Active’ ON.
- The ‘Separate product pricing’ setting for roles defaults to OFF and only applies to simple products, not variable products.
- Access rules only grant access to shoppers who have a WordPress user account. Guests who check out without creating an account will not receive access.
- Content restrictions are a display control mechanism and do not provide hard file or API security. Administrators can always see all content.
- The WooDonkey Companion plugin must be installed, active, and updated to the latest version on your WooCommerce store for these features to function. An empty roles list often indicates the plugin is missing or outdated.
Problems you may hit, and how to fix them
- Symptom: A customer bought a product linked to an access rule but did not receive the course or role.
Fix: Check if the customer completed the purchase as a guest without creating a WordPress user account. Access rules require a WordPress user to grant permissions. - Symptom: Content restricted by a rule is hidden from all visitors, including those who should have access.
Fix: Review the content restriction rule. If the ‘Visible to roles’ whitelist is empty, the content will be hidden from everyone except administrators. Select the appropriate roles. - Symptom: You need to temporarily disable an access rule, but there is no switch on the form.
Fix: Access rules are created as enabled, and the current form does not provide a way to turn them off. To stop an access rule from applying, you must delete it. - Symptom: The ‘LearnDash course’ option is missing from the ‘Permission type’ selector when creating an access rule.
Fix: Ensure that the LearnDash plugin is installed and active on your WooCommerce store. - Symptom: Separate product pricing is not working for variable products.
Fix: The ‘Separate product pricing’ feature for roles only applies to simple products, not variable products. - Symptom: The list of roles on the ‘Roles’ tab is empty or shows a loading message indefinitely.
Fix: Verify that the WooDonkey Companion plugin is installed, active, and updated to the latest version on your WooCommerce store. - Symptom: After deleting a custom role, some users who were assigned to it are now ‘Subscribers’.
Fix: When a role is deleted, any users whose *only* assigned role was the deleted one are automatically moved to the default ‘Subscriber’ role. Users with multiple roles will retain their other roles.